How to choose a CREST-accredited penetration testing provider: a 12-point checklist
Two penetration test quotes can look alike on paper and deliver very different things. One shows you how an attacker would actually get in. The other is a scanner printout with a logo on it. This checklist helps security and procurement teams tell them apart before signing.
Copy the questions into your tender. A provider that cannot answer several of them clearly is probably selling a scan.
Twelve questions to put to every provider
- Is the company CREST-accredited? Ask for its CREST membership details and check them yourself in CREST’s public member directory at crest-approved.org.
- Who will do the testing, and what certifications do they hold? Ask for anonymized CVs showing current CREST certifications such as CRT or CCT. Years of experience alone tell you little.
- Is the testing approach written down? Ask for the document. It should draw on public standards such as OWASP WSTG and ASVS, PTES or NIST SP 800-115. If there is no document, the testing is probably improvised.
- Is there a scoping workshop? Testers need time with your engineers to understand user roles and permissions. Without it, they will miss flaws in who can do what.
- Are the rules of engagement and NDA clear? Look for protection of systems that are out of scope, and terms for handling, keeping and deleting your data.
- How much of the work is manual? Ask what the testers do by hand and what the tools do. Work that is mostly automated tends to produce long lists of false alarms.
- Will the report show attack chains? A good report explains how several low-severity issues were combined into something serious, such as full control of your network.
- How are risks rated? CVSS, the common technical severity score, does not reflect business impact on its own. Ask whether they add a business-risk method such as the OWASP Risk Rating.
- Are findings mapped to your frameworks? For example ISO 27001, SOC 2, PCI DSS or GDPR, inside the report itself.
- Is a retest included? Look for a retest within an agreed window, often 30 days, at no extra cost. Otherwise you pay again to prove your fixes work.
- Is there a short executive summary? Two pages that a non-technical board can read and act on.
- Are the scope and delivery date fixed? Look for a fixed scope, a report date measured in days rather than weeks, and no open-ended day-rate billing.
Warning signs in a sales conversation
Be cautious if a provider offers to start tomorrow with no scoping, or plans to use one tester for all your applications. The same goes for a provider that will not share a sample report or wants to bill by the day with no fixed scope.
How Snipeyes answers these questions
We are CREST-accredited and certified to ISO/IEC 27001:2022, and our testers hold CREST certifications such as CRT and CCT. Our documented testing approach draws on OWASP WSTG and ASVS, PTES, NIST SP 800-115 and MITRE ATT&CK.
Every engagement starts with a 90-minute scoping workshop and runs under NDA. Our testers validate findings by hand and show how weaknesses chain together. We rate risk with both CVSS and the OWASP Risk Rating, and map findings to the frameworks you report against. You get a two-page executive summary and the full report within 10 business days of testing, with the retest included.